Malicious Office (OLE) — malware analysis report

Static analysis result for SHA-256 6af6f77864cdb2e1…

MALICIOUS

Office (OLE)

618.5 KB Created: 1601-01-01 00:00:00 Authoring application: Microsoft PowerPoint
MD5: a4b813bb5082872a2783c5f37e1e63a7 SHA-1: 9353cce3113466da6f66896fe754c859c41aa960 SHA-256: 6af6f77864cdb2e1e26fd3ae24a4f7da2cbf123ea93fd27df20267dc8ac6c2db
302 Risk Score

Malware Insights

MITRE ATT&CK
T1059.003 Windows Command Shell T1105 Ingress Tool Transfer

The sample exhibits high-confidence heuristics indicating the use of API hashing for resolving functions and suspicious invocation of cmd.exe. Crucially, it references the URLDownloadToFile API, suggesting an attempt to download additional content. The embedded URL points to a suspicious domain, likely serving as the source for a second-stage payload. The document body is heavily obfuscated and appears to contain shellcode or script fragments.

Heuristics 8

  • Reference to URLDownloadToFile API critical SC_STR_URLDOWNLOAD
    Reference to URLDownloadToFile API
  • x86 GetPC stub (CALL $+5; POP EAX) high SC_GETPC_CALL
    x86 GetPC stub (CALL $+5; POP EAX)
  • PEB access via FS segment (x86) high SC_PEB_ACCESS
    PEB access via FS segment (x86)
  • PEB API-hash resolver high SC_API_HASH_RESOLVER
    PEB access followed by ROR13-style API hashing, a common position-independent shellcode import resolver
  • Suspicious cmd.exe invocation with execution flag high SC_STR_CMD
    Suspicious cmd.exe invocation with execution flag
  • Reference to LoadLibrary API high SC_STR_LOADLIBRARY
    Reference to LoadLibrary API
  • Reference to GetProcAddress API high SC_STR_GETPROCADDRESS
    Reference to GetProcAddress API
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://bmwftp.blogdns.net:8080/nnn/#